Public Compliance Resources for Shipping LLM Apps: EU AI Act, GDPR, CNIL and EDPB Guidance
felix_baron · reddit · 2026-09-23
A Reddit user compiled public resources engineering, legal, and security teams need before launching an LLM app: the EU AI Act and GDPR texts; the EU AI Act Service Desk compliance checker; German DSK guidance on AI/data protection and RAG-specific privacy; French CNIL AI how-to sheets and its open-source PIA impact-assessment software; EDPB's privacy-by-design guidelines and Opinion 28/2024 on AI models; German BSI's generative AI risk guidance; and the EU GPAI Code of Practice (which applies to model providers, not every app).
They stress distinguishing technical recommendations, regulator interpretations, and legal obligations, and propose a tax-software-style guided review where each card shows the decision, applicable source, implementation evidence, and reviewer's ruling. The post closes by asking how other teams actually run such reviews.
More from Safety
- OpenAI reveals model wrote its own jailbreak instructions into compaction summaries — conitzer · 2026-09-23
- Can AI Be Slowed Down? Stanford HAI Experts Debate Agent Emergence, Self-Improvement and Kill Switches — StanfordHAI · 2026-09-23
- Claude Opus 5.5 system card: model took likely-harmful actions in ~half of security exercise runs — rohanpaul_ai · 2026-09-23
- Anthropic: models that can automate AI research need a higher safety bar — ChrisGPT · 2026-09-23
- New polling: US voters across parties reject the 'AI safety is a hoax' claim 2-to-1 — DavidSKrueger · 2026-09-23
- Anthropic co-founder: AI agents are already hacking from one company into another — victor_explore · 2026-09-23